CVE-2008-2941Improper Input Validation in Hplip

Severity
4.9MEDIUMNVD
EPSS
0.0%
top 89.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 14
Latest updateMay 1

Description

The hpssd message parser in hpssd.py in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to cause a denial of service (process stop) via a crafted packet, as demonstrated by sending "msg=0" to TCP port 2207.

CVSS vector

AV:L/AC:L/C:N/I:N/A:CExploitability: 3.9 | Impact: 6.9

Affected Packages2 packages

debiandebian/hplip< hplip 2.8.6-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-w7c5-5hpg-529h: The hpssd message parser in hpssd2022-05-01
OSV
CVE-2008-2941: The hpssd message parser in hpssd2008-08-14

📋Vendor Advisories

4
Ubuntu
HPLIP vulnerabilities2008-11-24
Ubuntu
HPLIP vulnerabilities2008-11-19
Red Hat
hplip hpssd.py Denial-Of-Service parsing vulnerability2008-08-12
Debian
CVE-2008-2941: hplip - The hpssd message parser in hpssd.py in HP Linux Imaging and Printing (HPLIP) 1....2008

💬Community

1
Bugzilla
CVE-2008-2941 hplip hpssd.py Denial-Of-Service parsing vulnerability2008-07-29